1 results (0.010 seconds)

CVSS: 9.0EPSS: 1%CPEs: 5EXPL: 1

diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote attackers to execute arbitrary OS commands via shell metacharacters in the ipaddr field of an HTTP GET request. diag_ping.cmd, en dispositivos D-Link DSL-2640U con firmware IM_1.00 and ME_1.00, y dispositivos DSL-2540U con firmware ME_1.00, permite que atacantes remotos autenticados ejecuten comandos arbitrarios del sistema operativo mediante metacaracteres shell en el campo ipaddr de una petición HTTP GET. • https://www.iplantom.com/2018/01/10/dsl2640U • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •